{"id":1053,"date":"2022-05-03T13:14:00","date_gmt":"2022-05-03T13:14:00","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=1053"},"modified":"2026-03-12T09:15:47","modified_gmt":"2026-03-12T08:15:47","slug":"data-protection-act-2018","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/en\/data-protection-act-2018\/","title":{"rendered":"UK Data Protection Act 2018 (DPA)"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-uk-data-protection-act-in-short\">UK Data Protection Act, in short<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-data-protection-act-2018-2021-update\">Data Protection Act 2018 \u2013 2021 update<\/h3>\n\n\n\n<p>The UK is no longer part of the European Union.<\/p>\n\n\n\n<p>This means changes to the legal landscape of data privacy and protection in the United Kingdom.<\/p>\n\n\n\n<p>The <strong>UK Data Protection Act 2018<\/strong>&nbsp;was actually passed in April 2016 and took effect (received Royal Assent) on May 25, 2018 \u2013 the same day as the <a href=\"\/en\/gdpr\/\">European General Data Protection Regulation (GDPR)<\/a>&nbsp;went into effect.<\/p>\n\n\n\n<p>This is no coincidence.<\/p>\n\n\n\n<p>The UK Data Protection Act&nbsp;was passed <strong>before the Brexit referendum<\/strong>&nbsp;later that summer and is in fact constructed around and meant to be read in conjunction with the EU GDPR, that has uniform authority over all member states.<\/p>\n\n\n\n<p>However, since the UK is no longer part of the EU, <strong>the European GDPR no longer has application domestically in the United Kingdom<\/strong>, and so the Data Protection Act of 2018 has been amended to accommodate the post-Brexit changes to UK data privacy law that have taken place.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4041\/alev-takil-7ojyp-ixw7w-unsplash.jpg?width=363&amp;\" alt=\"London skyline - Cookiebot\" width=\"770\" height=\"578\"\/><figcaption class=\"wp-element-caption\">After Brexit, the UK Data Protection Act no longer refers to the EU\u2019s GDPR, but to the UK-GDPR.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-data-protection-law-in-uk-after-brexit-2020\">Data protection law in UK after Brexit 2020<\/h3>\n\n\n\n<p>Here are the overall changes to UK data privacy law after Brexit \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The EU\u2019s GDPR has been lifted into a new <strong>UK-GDPR<\/strong>&nbsp;(United Kingdom General Data Protection Regulation) that took effect on January 31, 2020.<\/li>\n\n\n\n<li>The <strong>Data Protection Act 2018<\/strong>&nbsp;has been amended to be read in conjunction with the new UK-GDPR instead of the EU GDPR.<\/li>\n\n\n\n<li>An adequacy decision for the UK was adopted on June 28, 2021 by the EU, securing unrestricted flow of personal data between the two blocs until June 2025.<\/li>\n\n\n\n<li>It is likely that the UK government will move to consolidate the two amended laws (UK-GDPR and Data Protection Act 2018) into one, comprehensive piece of data protection law at a later point.<\/li>\n\n\n\n<li>It is likely that the EU will grant an adequacy decision before June 2021, removing the UK from the list of \u201cthird countries\u201d and ensuring unrestricted data flow between the two blocs.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/ec.europa.eu\/info\/files\/decision-adequate-protection-personal-data-united-kingdom-general-data-protection-regulation_en\/\" target=\"_blank\" rel=\"noreferrer noopener\">See the UK adequacy decision from June 2021<\/a><\/p>\n\n\n\n<p><a href=\"\/en\/uk-gdpr\/\">Lean more about the UK-GDPR<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/iapp.org\/news\/a\/faqs-for-uk-icos-data-transfer-consultation-including-approach-to-eu-sccs\/\" target=\"_blank\" rel=\"noreferrer noopener\">See the ICO\u2019s consultation on data transfers to and from the U.K. from August 2021<\/a><\/p>\n\n\n\n<p><a href=\"\/en\/gdpr-cookies\/\">Learn more about EU\u2019s GDPR and compliance<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cookiebot-cmp-and-uk-data-protection-act\">Cookiebot CMP and UK Data Protection Act<\/h2>\n\n\n\n<p>The UK has been protected and regulated by the <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR&nbsp;<\/a>since May 2018, but now that the country has left the EU, it has its own, equivalent set of data protection legislation.<\/p>\n\n\n\n<p>Our CMP is a world-leading consent management platform built specifically for the strong GDPR provisions of personal data protection, both in the EU and UK.<\/p>\n\n\n\n<p>Our solution scans your website and finds all cookies and similar tracking technologies, then blocks them all apart from the strictly necessary until the user has given their consent as to which they want to activate.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4333\/consent_en.png?width=500&amp;\" alt=\"Cookieboot Pop Up Banner - Cookiebot\" width=\"770\" height=\"449\"\/><figcaption class=\"wp-element-caption\">Cookiebot CMP standard consent banner for compliance with EU's GDPR and UK's Data Protection Act.<\/figcaption><\/figure>\n\n\n\n<p>This way, you can ensure that your website is in compliance with the requirements of obtaining prior consent from individuals, before collecting or processing their personal data.<\/p>\n\n\n\n<p>Under the new <strong>UK-GDPR<\/strong>&nbsp;and the amended <strong>UK Data Protection Act<\/strong>, users in the United Kingdom will have the same rights as users in the EU, and websites, companies and organizations who collect or process data of users in the UK will have to comply by the same requirements as those set out by the EU GDPR.<\/p>\n\n\n\n<p>Protecting users in the UK after Brexit requires the same insight, transparency and control of what happens on your website as before.<\/p>\n\n\n\n<p>This is what <a href=\"\/\">Cookiebot CMP<\/a>&nbsp;does best.<\/p>\n\n\n\n<p><a href=\"\/en\/gdpr-cookies\/\">Learn more about GDPR and consent<\/a><\/p>\n\n\n\n<p><a href=\"\/en\/uk-gdpr\/\">Learn more about the UK-GDPR<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-uk-data-protection-act-2018-in-detail\">UK Data Protection Act 2018, in detail<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-scope-substance-and-compliance-of-the-data-protection-act-2018\">Scope, substance and compliance of the Data Protection Act 2018<\/h3>\n\n\n\n<p>The <strong>Data Protection Act 2018<\/strong>&nbsp;is the UK\u2019s third generation of data protection legislation. It replaces the previous 1998 law by the same name and modernizes the country\u2019s legal framework in response to new technologies.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/3785\/thomas-kelley-8ie9ykf3us-unsplash.jpg?width=366&amp;\" alt=\"Big Ben clock face in London - Cookiebot\" width=\"770\" height=\"507\"\/><figcaption class=\"wp-element-caption\">Brexit means an amended Data Protection Act 2018 in the UK.<\/figcaption><\/figure>\n\n\n\n<p>The <strong>Data Protection Act 2018<\/strong>&nbsp;contains four parts that create four different \u201cdata protection regimes\u201d within the UK:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Part one is structured around the European GDPR, supplementing and tailoring it into domestic UK law.<\/li>\n\n\n\n<li>Part two extends beyond the EU GDPR and modifies it in certain cases to apply differently to UK law.<\/li>\n\n\n\n<li>Part three creates a new and separate regime for law enforcement authorities.<\/li>\n\n\n\n<li>Part four creates a new and separate regime for the UK\u2019s intelligence services.<\/li>\n<\/ol>\n\n\n\n<p>The <strong>general processing regime<\/strong>&nbsp;found in Part 2, Chapter 2 of the Data Protection Act appropriates and supplements the EU GDPR.<\/p>\n\n\n\n<p>Most of the processing of personal data is subject to the EU GDPR, and so the Data Protection Act refers to the GDPR\u2019s most central provisions for the protection of personal data.<\/p>\n\n\n\n<p>These include \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Requiring personal data to be processed lawfully and fairly, on the basis of the data subject\u2019s consent or another specified legal basis.<\/li>\n\n\n\n<li>Conferring rights on the data subject to obtain information about the processing of personal data and to require inaccurate personal data to be rectified.<\/li>\n\n\n\n<li>Conferring functions on the Commissioner, giving the holder of that office responsibility for monitoring and enforcing their provisions.<\/li>\n<\/ul>\n\n\n\n<p>The <strong>Data Protection Act 2018<\/strong>&nbsp;also adopts the central definitions of the EU GDPR, such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Personal data meaning \u201cany information relating to an identified or identifiable living individual.\u201d<\/li>\n\n\n\n<li>Processing meaning&nbsp;<em>\u201can operation or set of operations which is performed on information,\u201d<\/em>&nbsp;such as collection, recording, storage, disclosure, combination etc.<\/li>\n\n\n\n<li>Data subject meaning&nbsp;<em>\u201cliving individual to whom personal data relates.\u201d<\/em><\/li>\n\n\n\n<li>Controller and processor meaning the&nbsp;<em>\u201cnatural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.\u201d<\/em><\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4042\/shai-pal-dehe_mkktvs-unsplash.jpg?width=375&amp;\" alt=\"Fountain with London Bridge in the background at night - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">The UK Data Protection Act 2018 supports the domestic UK-GDPR instead of the EU\u2019s GDPR.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-where-the-uk-data-protection-act-extends-beyond-the-eu-gdpr\">Where the UK Data Protection Act extends beyond the EU GDPR<\/h3>\n\n\n\n<p>Apart from referring to the UK-GDPR instead of the EU\u2019s GDPR (since the UK has left the EU), the Data Protection Act 2018 creates additional provisions to the processing of personal data that goes beyond both the <a href=\"\/en\/uk-gdpr\/\">UK-GDPR<\/a>&nbsp;and the <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>.<\/p>\n\n\n\n<p>These are mostly found in the area of <strong>national security<\/strong>, <strong>law enforcement<\/strong>&nbsp;and <strong>immigration<\/strong>.<\/p>\n\n\n\n<p>In the area of national security, which lies outside the scope of the EU GDPR, the Data Protection Act applies the same requirements for personal data processing to the UK intelligence services.<\/p>\n\n\n\n<p>In the area of immigration, the Data Protection Act grants the UK Home Office the power to refuse personal data access requests based on the risk it could pose to immigration enforcement.<\/p>\n\n\n\n<p>In addition, the Data Protection Act frames the role \u2013 jurisdiction, function and powers \u2013 of the <a href=\"https:\/\/ico.org.uk\/\" target=\"_blank\" rel=\"noreferrer noopener\">Information Commissioner (ICO)<\/a>&nbsp;as the leading data protection authority (DPA) in the UK.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2018\/12\/pdfs\/ukpga_20180012_en.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Read the Data Protection Act 2018 law text here (pdf)<\/a><\/p>\n\n\n\n<p><a href=\"\/en\/uk-gdpr\/\">Learn more about the UK-GDPR<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-brexit-and-uk-data-protection-act-in-2021\">Brexit and UK Data Protection Act in 2021<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-new-and-amended-uk-data-protection-act\">The new and amended UK Data Protection Act<\/h3>\n\n\n\n<p>Now that Brexit has happened, several legal changes has taken effect in the area of data protection.<\/p>\n\n\n\n<p>The EU Withdrawal Agreement that&nbsp;took effect on Exit Day specifies that the UK&nbsp;<em>\u201cshall ensure a level of protection of personal data essentially equivalent to that under Union law\u201d<\/em>&nbsp;(<strong>Article 71<\/strong>).<\/p>\n\n\n\n<p>This is important because of <a href=\"https:\/\/gdpr-info.eu\/art-45-gdpr\/\" target=\"_blank\" rel=\"noreferrer noopener\">Article 45<\/a>&nbsp;in the European GDPR, which requires countries that are not part of the EU to have <strong>an adequate level<\/strong>&nbsp;of domestic data protection laws in order to ensure a free flow of information to and from the EU.<\/p>\n\n\n\n<p>However, on June 28, 2021, the EU adopted an adequacy decision for the UK, meaning that websites, companies and organizations in the United Kingdom who process personal data from users inside of the EU can carry on as before, business-as-usual for the next four years (until June 2025).<\/p>\n\n\n\n<p><a href=\"https:\/\/ec.europa.eu\/info\/files\/decision-adequate-protection-personal-data-united-kingdom-general-data-protection-regulation_en\/\" target=\"_blank\" rel=\"noreferrer noopener\">See the UK adequacy decision from June 2021<\/a><\/p>\n\n\n\n<p><a href=\"\/en\/uk-gdpr\/\">Lean more about the UK-GDPR<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/3786\/luke-stackpoole-moeqotmupg8-unsplash.jpg?width=364&amp;\" alt=\"London skyline with Big Ben clock face in the centre - Cookiebot\" width=\"770\" height=\"588\"\/><figcaption class=\"wp-element-caption\">The UK Data Protection Act 2018 supports the domestic UK-GDPR instead of the EU\u2019s GDPR.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-new-data-protection-act-2018-and-a-new-gdpr\">New Data Protection Act 2018 and a new GDPR<\/h3>\n\n\n\n<p>The <strong>UK-GDPR<\/strong>&nbsp;(United Kingdom General Data Protection Regulation)&nbsp;is in effect in the UK and&nbsp;will be read in conjunction with the newly amended <strong>Data Protection Act 2018<\/strong>&nbsp;(DPA 2018).<\/p>\n\n\n\n<p>The&nbsp;<em>Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019<\/em>&nbsp;(<strong>DPPEC Regulations<\/strong>) is the statutory instrument amending both the GDPR (turning it into the new <strong>UK-GDPR<\/strong>) and the <strong>Data Protection Act 2018<\/strong>.<\/p>\n\n\n\n<p><a href=\"http:\/\/www.legislation.gov.uk\/ukdsi\/2019\/9780111177594\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read the DPPEC regulations here.<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-important-amendments-to-the-uk-data-protection-act-2018\">Important amendments to the UK Data Protection Act 2018<\/h3>\n\n\n\n<p>The most important amendments to the Data Protection Act include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The first two parts of the Data Protection Act that are currently referring to the EU GDPR&nbsp;has been amended&nbsp;to refer to the new UK-GDPR instead of the EU GDPR.<\/li>\n\n\n\n<li>All places in the Data Protection Act where the law refers to EU legislation and institutions are changed to the UK equivalents.<\/li>\n\n\n\n<li>The Information Commissioner (ICO) will become the lead enforcer of the Data Protection Act and the UK-GDPR instead of the lead supervisor in the EU of the European GDPR.<\/li>\n\n\n\n<li>The Data Protection Act deems all EAA\/EU countries (including Gibraltar) as adequate.<\/li>\n\n\n\n<li>The Data Protection Act also integrates all EU adequacy decisions made prior to Brexit, e.g. the US Privacy Shield program.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/3787\/massimiliano-morosinotto-paink01g8xk-unsplash.jpg?width=412&amp;\" alt=\"House of parliment and Big Ben  - Cookiebot\" width=\"770\" height=\"571\"\/><figcaption class=\"wp-element-caption\">New data protection laws in the UK&nbsp;took effect on Exit Day January 31, 2020.<\/figcaption><\/figure>\n\n\n\n<p>These <strong>DPPEC Regulations<\/strong>&nbsp;can be viewed in the following Keeling Schedules showing&nbsp;the changes that took effect on Exit Day (January 31, 2020).<\/p>\n\n\n\n<p><a href=\"https:\/\/www.gov.uk\/government\/publications\/data-protection-law-eu-exit\/\" target=\"_blank\" rel=\"noreferrer noopener\">Keeling Schedule for the amendments to the Data Protection Act 2018.<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.gov.uk\/government\/publications\/data-protection-law-eu-exit\/\" target=\"_blank\" rel=\"noreferrer noopener\">Keeling Schedule for the creation of the new UK-GDPR.<\/a><\/p>\n\n\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>UK Data Protection Act, in short Data Protection Act 2018 \u2013 2021 update The UK is no longer part of the European Union. This means changes to the legal landscape of data privacy and protection in the United Kingdom. The UK Data Protection Act 2018&nbsp;was actually passed in April 2016 and took effect (received Royal [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":1073,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1053","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/05\/henry-be-mdjq0zfuwrw-unsplash_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/1053","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/comments?post=1053"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/1053\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media\/1073"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media?parent=1053"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/categories?post=1053"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/tags?post=1053"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}