Data Protection Act 2018: Summary & Key Principles
In the UK, data protection is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This legislation controls how personal information is used by different organisations such as businesses and government departments. Anyone who is responsible for using personal data must make sure that it is handled in a way that ensures appropriate security. Failure to do so can result in damaged business reputation and hefty fines of up to £17 million. As such, it is vital that anyone who handles personal data fully understands their legal duty and the responsibilities that the Act places upon them. In this article we will outline what the Data Protection Act 2018 is and its core principles.
What is the Data Protection Act 2018?
The Data Protection Act 2018 is a key piece of legislation in the UK that governs data protection, seeking to ensure that personal data is protected and handled appropriately and responsibly. The Act positions the Information Commissioner’s Office (ICO) as the UK’s independent data protection regulator. It also places a duty on data controllers to notify the Information Commissioner, as well as the relevant individuals, about any data breaches that risk affecting an individuals’ rights.

The Act reflects the risks that technological advancements bring by helping people have more control over their personal data, especially as this kind of data is processed now more than ever. Moreover, in 2016 the European Union (EU) introduced the General Data Protection Regulation (GDPR) which necessitated new data privacy and security laws for organisations around the world. It imposed an obligation on organisations, both inside and outside of the EU, to adhere to seven protection and accountability principles. The UK is no longer part of the EU and so the Act, alongside the UK General Data Protection Regulation (UK GDPR), reflects an adaptation of EU guidelines to suit data processing in the UK.
Under the Act, data subjects have rights regarding their personal information. These rights are:
- The right to be informed about data collection and the use of their personal data
- The right to access personal data and supplementary information
- The right to have inaccurate personal data rectified or completed if it’s incomplete
- The right to erasure in certain circumstances
- The right to restrict processing in certain circumstances
- The right to data portability, which allows the data subject to obtain and reuse their personal data for their own purposes across different services
- The right to object to processing in certain circumstances
- Rights in relation to automated decision making and profiling
- The right to withdraw consent at any time (where relevant)
- The right to complain to the Information Commissioner
Looking for More?
Failure to comply with data protection legislation can result in hefty fines as well as a damaged reputation. Our Data Protection & UK GDPR Training is designed to help businesses comply with the essential principles of the Act, protecting customers and keeping businesses legally compliant.
Who Does the Data Protection Act Apply to?
Any business or person who uses or holds an individual’s personal data within the EU or UK must adhere to the Data Protection Act 2018. Breaching the Act is a criminal offence and can result in severe penalties.
Core Principles of the Data Protection Act
There are seven principles at the core of the Act. These principles are:
Lawfulness, Fairness, Transparency
All personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject. Lawfulness refers to the processing of personal data by a data controller which must have a legal basis under the UK GDPR and comply with requirements of the UK GDPR and the Act. The processing of data must not involve any otherwise unlawful processing or use of personal data. Fairness refers to the processing of any personal data and necessitates that it be fair in order to avoid processing being unduly detrimental, unexpected, misleading or deceptive. Transparency ensures that personal data processing is clear and transparent to individuals and regulators. Data controllers must inform individuals about how their personal data will be processed in an accessible and easily understandable manner.
The ICO summarises the first principle as follows:
- Controllers must identify valid grounds under the UK GDPR for collecting and using personal data.
- Controllers must ensure that they do not do anything with the data in breach of any other laws.
- Controllers must use personal data in a way that is fair. This means they must not process the data in a way that is unduly detrimental, unexpected or misleading to the individuals concerned.
- Controllers must be clear, open and honest with people from the start about how they will use their personal data.
The UK GDPR defines a controller as ‘the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.’ The ICO states that a controller can be a company or other legal entity (such as an incorporated partnership, incorporated association or public authority), or an individual (such as a sole trader, partner in an unincorporated partnership, or self-employed professional, e.g. a barrister).
Purpose Limitation
Personal data must only be collected for the ‘specified, explicit and legitimate purposes’ determined at the time of collection. Personal data must not be further processed in a manner that is incompatible with those purposes. However, where there are sufficient safeguards in place, data controllers may undertake further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes if those purposes are not considered incompatible with the initial purposes.
This principle seeks to ensure that controllers are clear and open about the proposed processing of personal data from the onset and that the purposes of data processing are in line with an individual’s reasonable expectations.
The ICO summarises the second principle as follows:
- Controllers must be clear about their purpose for processing personal information from the start.
- Controllers must record their purposes as part of their documentation obligations and specify in them their privacy information.
- Controllers must only reuse the personal information for a new purpose if this is compatible with the original purpose.
- Controllers must have a lawful basis for any new purpose. If their original lawful basis is not sufficient, they must find a new one.
Data Minimisation
Data minimisation mandates that controllers only collect and process personal data that is adequate, relevant and limited to what is necessary for the purpose for which it is being processed. Data controllers should collect the minimum amount of data they require for their intended processing purposes and they should never collect unnecessary personal data.
The data minimisation principle supports data protection by limiting the amount of personal data which could be lost or stolen. This assists in ensuring the integrity and confidentiality of personal data and makes it easier for organisations to ensure that the data they hold is accurate and up-to-date.
The ICO summarises the third principle as follows:
- Controllers must ensure that the personal data they are processing is:
- Adequate – sufficient to properly fulfil the stated purpose
- Relevant – has a rational link to that purpose
- Limited to what is necessary – controllers must not hold more personal data than needed for the intended purpose
Accuracy
The accuracy principle mandates that all personal data collected, stored or otherwise processed by a controller must be accurate and where necessary, kept up-to-date. Data controllers should take all reasonable steps to ensure that any inaccurate personal data is erased or rectified as soon as possible.
All reasonable steps must be taken to correct any inaccuracies in a timely manner. As such, controllers must have clear procedures in place for correcting or erasing any inaccurate data that they may hold.
The ICO summarises the fourth principle as follows:
- Controllers should take all reasonable steps to ensure the personal data they hold is not incorrect or misleading as to any matter of fact.
- Controllers may need to keep the personal data updated, although this will depend on what they are using it for.
- If a controller discovers that personal data is incorrect or misleading, they must take reasonable steps to correct or erase it as soon as possible.
- Controllers must carefully consider any challenges to the accuracy of personal data.
Storage Limitation
Controllers must hold personal data for no longer than is necessary. Personal data which permits the identification of individuals must not be held longer than necessary for the purposes for which the personal data is being processed. Personal data may be stored for a longer period where it is being processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with UK GDPR. This data must only be held for as long as there are robust technical and organisational measures to safeguard the rights and freedoms of the individual.
Subsequently, controllers should generally delete personal data as soon as it ceases to be necessary for the purpose for which it was originally collected. It is therefore recommended that time limits are established by the controller for the erasure or periodic review of personal data. In line with the transparency principle, controllers should ensure that individuals are aware of retention periods or how these periods are calculated. Controllers who retain personal data in an offline manner, such as hard copy files, regardless of whether the digital copy has been deleted, must still have justification for retaining personal data in this form and respond to data subject requests.
The ICO summariseS the fifth principle as follows:
- Controllers must not keep personal data for longer than they need it.
- Controllers need to think about – and be able to justify – how long they keep personal data. This will depend on their purpose for holding the data.
- Controllers need a policy that sets standard retention periods, wherever possible, to comply with documentation requirements.
- Controllers should also periodically review the data they hold and erase or anonymise it when they no longer need it.
- Controllers must carefully consider any challenges to the retention of data. Individuals have a right to erasure if controllers no longer need the data.
- Controllers can keep personal data for longer if they are only keeping it for public interest archiving, scientific or historical research or statistical purposes.
Integrity and Confidentiality (Security)
The integrity and confidentiality principle, also known as the security principle, mandates that controllers only process personal data in a manner that ensures appropriate levels of security and confidentiality. This includes protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. Controllers must utilise appropriate technical or organisational measures to support this. Controllers must ensure that their security measures effectively protect against accidental or deliberate harm, loss, or dissemination of the personal data that they process. These measures must include cybersecurity measures and physical and organisational security measures. Organisations must routinely check that these measures are up-to-date and effective.
As technological threats are constantly evolving, organisations should consider a range of security options and should ensure their security measures are also adapting to meet modern challenges.
The ICO summarises the sixth principle as follows:
- Controllers must ensure that they have appropriate security measures in place to protect the personal data they hold.
Accountability
The accountability principle specifically states that controllers are responsible for, and must be able to demonstrate compliance with, the other principles of data protection. Controllers must ensure that they comply with all the principles of data protection and that they have appropriate measures and records in place to demonstrate compliance. Compliance with the other principles of data protection will assist in accountability as well as adopting additional measures such as creating internal policies, following codes of conduct or certification schemes, recording and reporting personal data breaches and implementing appropriate privacy policies and notices.
Accountability obligations are ever evolving and controllers should continually review and update their accountability measures.
The ICO summarises the seventh principle as follows:
- Controllers must have appropriate measures and records in place to be able to demonstrate their compliance.
- Controllers are required to take responsibility for what they do with personal data and how they comply with the other principles of data protection.
Data (Use and Access) Act 2025
The Data (Use and Access) Act 2025 (DUAA) received royal assent in June 2025. It seeks to modernise how data is used, shared and protected across the UK. Alongside a wide range of reforms, the Act makes important changes to UK data protection and privacy laws. You can read our article on the DUAA and gain a more detailed understanding of the Act here.

The ICO notes that changes made by the act may change elements of the Data Protection Act 2018. That being said, the DUAA does not replace UK GDPR or the Data Protection Act 2018. Instead it makes amendments and introduces changes in order to promote innovation and economic growth as well as to make things easier for organisations. You can find the ICO’s comprehensive overview of these changes, in the same order and headings as the DUAA, here.
It’s worth noting that the ICO overview is aimed at experts such as data protection officers and people with specific data protection responsibilities. The overview has particular focus on what has changed rather than being an explanation about data protection law. As such, the guidance should be read by people who already understand the current law. The ICO has a more brief overview of the changes for organisations here.
Robust data protection measures are vital to protecting personal data. People must be able to trust their personal data is being handled safely and in compliance with the law. Organisations that fail to adhere to the tenets of the Data Protection Act 2018 or the Data (Use and Access) Act 2025 can unnecessarily put people at risk of harm and face severe penalties.
Further Resources:
- Data Protection & UK GDPR Training
- The Data (Use and Access) Act (DUAA) 2025 Summary
- The Consequences of a Lack of Training in the Workplace




