{"id":123,"date":"2026-07-20T09:30:00","date_gmt":"2026-07-20T08:30:00","guid":{"rendered":"https:\/\/www.highspeedtraining.co.uk\/hub\/?p=123"},"modified":"2026-07-21T16:50:25","modified_gmt":"2026-07-21T15:50:25","slug":"data-protection-act-summary","status":"publish","type":"post","link":"https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/","title":{"rendered":"Data Protection Act 2018: Summary &amp; Key Principles"},"content":{"rendered":"\n<p>In the UK, data protection is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This legislation controls how personal information is used by different organisations such as businesses and government departments. Anyone who is responsible for using personal data must make sure that it is handled in a way that ensures appropriate security. Failure to do so can result in damaged business reputation and hefty fines of up to \u00a317 million. As such, it is vital that anyone who handles personal data fully understands their legal duty and the responsibilities that the Act places upon them. In this article we will outline what the Data Protection Act 2018 is and its core principles.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-data-protection-act-2018\">What is the Data Protection Act 2018?&nbsp;<\/h2>\n\n\n\n<p>The <a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2018\/12\/contents\" target=\"_blank\" rel=\"noreferrer noopener\">Data Protection Act 2018<\/a> is a key piece of legislation in the UK that governs data protection, seeking to ensure that personal data is protected and handled appropriately and responsibly. The Act positions the <a href=\"https:\/\/ico.org.uk\/\" target=\"_blank\" rel=\"noreferrer noopener\">Information Commissioner\u2019s Office<\/a> (ICO) as the UK\u2019s independent data protection regulator. It also places a duty on data controllers to notify the Information Commissioner, as well as the relevant individuals, about any data breaches that risk affecting an individuals\u2019 rights.\u00a0<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"685\" height=\"295\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2026\/07\/data-1.jpg\" alt=\"Typing on a laptop\" class=\"wp-image-83128\"\/><\/figure><\/div>\n\n\n<p>The Act reflects the risks that technological advancements bring by helping people have more control over their personal data, especially as this kind of data is processed now more than ever. Moreover, in 2016 the European Union (EU) introduced the General Data Protection Regulation (GDPR) which necessitated new data privacy and security laws for organisations around the world. It imposed an obligation on organisations, both inside and outside of the EU, to adhere to seven protection and accountability principles. The UK is no longer part of the EU and so the Act, alongside the <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/contents\" target=\"_blank\" rel=\"noreferrer noopener\">UK General Data Protection Regulation<\/a> (UK GDPR), reflects an adaptation of EU guidelines to suit data processing in the UK.\u00a0<\/p>\n\n\n\n<p>Under the Act, data subjects have rights regarding their personal information. These rights are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The right to be informed about data collection and the use of their personal data<\/li>\n\n\n\n<li>The right to access personal data and supplementary information<\/li>\n\n\n\n<li>The right to have inaccurate personal data rectified or completed if it\u2019s incomplete<\/li>\n\n\n\n<li>The right to erasure in certain circumstances<\/li>\n\n\n\n<li>The right to restrict processing in certain circumstances<\/li>\n\n\n\n<li>The right to data portability, which allows the data subject to obtain and reuse their personal data for their own purposes across different services<\/li>\n\n\n\n<li>The right to object to processing in certain circumstances<\/li>\n\n\n\n<li>Rights in relation to automated decision making and profiling<\/li>\n\n\n\n<li>The right to withdraw consent at any time (where relevant)\u00a0<\/li>\n\n\n\n<li>The right to complain to the Information Commissioner\u00a0<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-gutenberg-hst-block-experttip tip__box\"><div class=\"tip__title__container\"><div class=\"tip__title__text\"><div class=\"tip__title__icon\"><img decoding=\"async\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/plugins\/hub-custom-blocks-plugin\/expert-tip-icon.png\" alt=\"Expert Icon\"\/><\/div><h3>Looking for More?<\/h3><\/div><\/div><p>Failure to comply with data protection legislation can result in hefty fines as well as a damaged reputation. Our <a href=\"https:\/\/www.highspeedtraining.co.uk\/courses\/business-essentials\/data-protection-course\/\" target=\"_blank\" rel=\"noreferrer noopener\">Data Protection &amp; UK GDPR Training<\/a> is designed to help businesses comply with the essential principles of the Act, protecting customers and keeping businesses legally compliant.<\/p><\/div>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-does-the-data-protection-act-apply-to\">Who Does the Data Protection Act Apply to?\u00a0<\/h4>\n\n\n\n<p>Any business or person who uses or holds an individual&#8217;s personal data within the EU or UK must adhere to the Data Protection Act 2018. Breaching the Act is a criminal offence and can result in severe penalties.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-core-principles-of-the-data-protection-act\">Core Principles of the Data Protection Act<\/h2>\n\n\n\n<p>There are seven principles at the core of the Act. These principles are:<\/p>\n\n\n\n<div class=\"accordion\">\n    <h3>\n        Lawfulness, Fairness, Transparency        <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2015\/09\/down53.png\" alt=\"drop down menu\" width=\"24\" height=\"24\" \/>\n    <\/h3>\n    <div>\n    <p><span style=\"font-weight: 400;\">All personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject. Lawfulness refers to the processing of personal data by a data controller which must have a legal basis under the UK GDPR and comply with requirements of the UK GDPR and the Act. The processing of data must not involve any otherwise unlawful processing or use of personal data. Fairness refers to the processing of any personal data and necessitates that it be fair in order to avoid processing being unduly detrimental, unexpected, misleading or deceptive. Transparency ensures that personal data processing is clear and transparent to individuals and regulators. Data controllers must inform individuals about how their personal data will be processed in an accessible and easily understandable manner.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The ICO summarises the <\/span><a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/data-protection-principles\/a-guide-to-the-data-protection-principles\/lawfulness-fairness-and-transparency\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">first principle<\/span><\/a><span style=\"font-weight: 400;\"> as follows:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must identify valid grounds under the UK GDPR for collecting and using personal data.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must ensure that they do not do anything with the data in breach of any other laws.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must use personal data in a way that is fair. This means they must not process the data in a way that is unduly detrimental, unexpected or misleading to the individuals concerned.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must be clear, open and honest with people from the start about how they will use their personal data.<\/span><\/li>\n<\/ul>\n<div class=\"wp-block-gutenberg-hst-block-plaintextbox boxed\">\n<p>The UK GDPR defines a controller as \u2018the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.\u2019 The ICO states that a controller can be a company or other legal entity (such as an incorporated partnership, incorporated association or public authority), or an individual (such as a sole trader, partner in an unincorporated partnership, or self-employed professional, e.g. a barrister).<\/p>\n<\/div>\n    <\/div>\n        <h3>\n        Purpose Limitation         <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2015\/09\/down53.png\" alt=\"drop down menu\" width=\"24\" height=\"24\" \/>\n    <\/h3>\n    <div>\n    <p><span style=\"font-weight: 400;\">Personal data must only be collected for the \u2018specified, explicit and legitimate purposes\u2019 determined at the time of collection. Personal data must not be further processed in a manner that is incompatible with those purposes. However, where there are sufficient safeguards in place, data controllers may undertake further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes if those purposes are not considered incompatible with the initial purposes.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This principle seeks to ensure that controllers are clear and open about the proposed processing of personal data from the onset and that the purposes of data processing are in line with an individual\u2019s reasonable expectations.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The ICO summarises the <\/span><a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/data-protection-principles\/a-guide-to-the-data-protection-principles\/purpose-limitation\/#why\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">second principle<\/span><\/a><span style=\"font-weight: 400;\"> as follows:\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must be clear about their purpose for processing personal information from the start.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must record their purposes as part of their documentation obligations and specify in them their privacy information.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must only reuse the personal information for a new purpose if this is compatible with the original purpose.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must have a lawful basis for any new purpose. If their original lawful basis is not sufficient, they must find a new one.\u00a0<\/span><\/li>\n<\/ul>\n    <\/div>\n        <h3>\n        Data Minimisation         <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2015\/09\/down53.png\" alt=\"drop down menu\" width=\"24\" height=\"24\" \/>\n    <\/h3>\n    <div>\n    <p><span style=\"font-weight: 400;\">Data minimisation mandates that controllers only collect and process personal data that is adequate, relevant and limited to what is necessary for the purpose for which it is being processed. Data controllers should collect the minimum amount of data they require for their intended processing purposes and they should never collect unnecessary personal data.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The data minimisation principle supports data protection by limiting the amount of personal data which could be lost or stolen. This assists in ensuring the integrity and confidentiality of personal data and makes it easier for organisations to ensure that the data they hold is accurate and up-to-date.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The ICO summarises the <\/span><a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/data-protection-principles\/a-guide-to-the-data-protection-principles\/data-minimisation\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">third principle<\/span><\/a><span style=\"font-weight: 400;\"> as follows:\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must ensure that the personal data they are processing is:<\/span>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Adequate \u2013 sufficient to properly fulfil the stated purpose<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Relevant \u2013 has a rational link to that purpose<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Limited to what is necessary \u2013 controllers must not hold more personal data than needed for the intended purpose<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n    <\/div>\n        <h3>\n        Accuracy         <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2015\/09\/down53.png\" alt=\"drop down menu\" width=\"24\" height=\"24\" \/>\n    <\/h3>\n    <div>\n    <p><span style=\"font-weight: 400;\">The accuracy principle mandates that all personal data collected, stored or otherwise processed by a controller must be accurate and where necessary, kept up-to-date. Data controllers should take all reasonable steps to ensure that any inaccurate personal data is erased or rectified as soon as possible.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">All reasonable steps must be taken to correct any inaccuracies in a timely manner. As such, controllers must have clear procedures in place for correcting or erasing any inaccurate data that they may hold.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The ICO summarises the <\/span><a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/data-protection-principles\/a-guide-to-the-data-protection-principles\/accuracy\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">fourth principle<\/span><\/a><span style=\"font-weight: 400;\"> as follows:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers should take all reasonable steps to ensure the personal data they hold is not incorrect or misleading as to any matter of fact.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers may need to keep the personal data updated, although this will depend on what they are using it for.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">If a controller discovers that personal data is incorrect or misleading, they must take reasonable steps to correct or erase it as soon as possible.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must carefully consider any challenges to the accuracy of personal data. <\/span><\/li>\n<\/ul>\n    <\/div>\n        <h3>\n        Storage Limitation         <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2015\/09\/down53.png\" alt=\"drop down menu\" width=\"24\" height=\"24\" \/>\n    <\/h3>\n    <div>\n    <p><span style=\"font-weight: 400;\">Controllers must hold personal data for no longer than is necessary. Personal data which permits the identification of individuals must not be held longer than necessary for the purposes for which the personal data is being processed. Personal data may be stored for a longer period where it is being processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with UK GDPR. This data must only be held for as long as there are robust technical and organisational measures to safeguard the rights and freedoms of the individual.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Subsequently, controllers should generally delete personal data as soon as it ceases to be necessary for the purpose for which it was originally collected. It is therefore recommended that time limits are established by the controller for the erasure or periodic review of personal data. In line with the transparency principle, controllers should ensure that individuals are aware of retention periods or how these periods are calculated. Controllers who retain personal data in an offline manner, such as hard copy files, regardless of whether the digital copy has been deleted, must still have justification for retaining personal data in this form and respond to data subject requests.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The ICO summariseS the <\/span><a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/data-protection-principles\/a-guide-to-the-data-protection-principles\/storage-limitation\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">fifth principle<\/span><\/a><span style=\"font-weight: 400;\"> as follows:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must not keep personal data for longer than they need it.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers need to think about &#8211; and be able to justify &#8211; how long they keep personal data. This will depend on their purpose for holding the data.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers need a policy that sets standard retention periods, wherever possible, to comply with documentation requirements.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers should also periodically review the data they hold and erase or anonymise it when they no longer need it.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must carefully consider any challenges to the retention of data. Individuals have a right to erasure if controllers no longer need the data.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers can keep personal data for longer if they are only keeping it for public interest archiving, scientific or historical research or statistical purposes.\u00a0<\/span><\/li>\n<\/ul>\n    <\/div>\n        <h3>\n        Integrity and Confidentiality (Security)         <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2015\/09\/down53.png\" alt=\"drop down menu\" width=\"24\" height=\"24\" \/>\n    <\/h3>\n    <div>\n    <p><span style=\"font-weight: 400;\">The integrity and confidentiality principle, also known as the security principle, mandates that controllers only process personal data in a manner that ensures appropriate levels of security and confidentiality. This includes protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. Controllers must utilise appropriate technical or organisational measures to support this. Controllers must ensure that their security measures effectively protect against accidental or deliberate harm, loss, or dissemination of the personal data that they process. These measures must include cybersecurity measures and physical and organisational security measures. Organisations must routinely check that these measures are up-to-date and effective.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As technological threats are constantly evolving, organisations should consider a range of security options and should ensure their security measures are also adapting to meet modern challenges.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The ICO summarises the <\/span><a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/data-protection-principles\/a-guide-to-the-data-protection-principles\/integrity-and-confidentiality-security\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">sixth principle<\/span><\/a><span style=\"font-weight: 400;\"> as follows:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must ensure that they have appropriate security measures in place to protect the personal data they hold.\u00a0<\/span><\/li>\n<\/ul>\n    <\/div>\n        <h3>\n        Accountability         <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2015\/09\/down53.png\" alt=\"drop down menu\" width=\"24\" height=\"24\" \/>\n    <\/h3>\n    <div>\n    <p><span style=\"font-weight: 400;\">The accountability principle specifically states that controllers are responsible for, and must be able to demonstrate compliance with, the other principles of data protection. Controllers must ensure that they comply with all the principles of data protection and that they have appropriate measures and records in place to demonstrate compliance. Compliance with the other principles of data protection will assist in accountability as well as adopting additional measures such as creating internal policies, following codes of conduct or certification schemes, recording and reporting personal data breaches and implementing appropriate privacy policies and notices.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Accountability obligations are ever evolving and controllers should continually review and update their accountability measures.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The ICO summarises the <\/span><a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/data-protection-principles\/a-guide-to-the-data-protection-principles\/accountability-principle\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">seventh principle<\/span><\/a><span style=\"font-weight: 400;\"> as follows:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers must have appropriate measures and records in place to be able to demonstrate their compliance.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controllers are required to take responsibility for what they do with personal data and how they comply with the other principles of data protection. <\/span><\/li>\n<\/ul>\n    <\/div>\n    <\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-data-use-and-access-act-2025\">Data (Use and Access) Act 2025<\/h4>\n\n\n\n<p>The <a href=\"https:\/\/www.highspeedtraining.co.uk\/hub\/data-use-and-access-act-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\">Data (Use and Access) Act 2025<\/a> (DUAA) received royal assent in June 2025. It seeks to modernise how data is used, shared and protected across the UK. Alongside a wide range of reforms, the Act makes important changes to UK data protection and privacy laws. You can read our article on the DUAA and gain a more detailed understanding of the Act <a href=\"https:\/\/www.highspeedtraining.co.uk\/hub\/data-use-and-access-act-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.\u00a0<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"685\" height=\"295\" src=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2026\/07\/data-2.jpg\" alt=\"Pile of papers on a desk\" class=\"wp-image-83129\"\/><\/figure><\/div>\n\n\n<p>The ICO notes that changes made by the act may change elements of the Data Protection Act 2018. That being said, the DUAA does not replace UK GDPR or the Data Protection Act 2018. Instead it makes amendments and introduces changes in order to promote innovation and economic growth as well as to make things easier for organisations. You can find the ICO\u2019s comprehensive overview of these changes, in the same order and headings as the DUAA, <a href=\"https:\/\/ico.org.uk\/about-the-ico\/what-we-do\/legislation-we-cover\/data-use-and-access-act-2025\/the-data-use-and-access-act-2025-duaa-summary-of-the-changes\/data-protection\/\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.\u00a0<\/p>\n\n\n\n<p>It\u2019s worth noting that the ICO overview is aimed at experts such as data protection officers and people with specific data protection responsibilities. The overview has particular focus on what has <em>changed <\/em>rather than being an explanation about data protection law. As such, the guidance should be read by people who already understand the current law. The ICO has a more brief overview of the changes for organisations <a href=\"https:\/\/ico.org.uk\/about-the-ico\/what-we-do\/legislation-we-cover\/data-use-and-access-act-2025\/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations\/\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.\u00a0<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><em>Robust data protection measures are vital to protecting personal data. People must be able to trust their personal data is being handled safely and in compliance with the law. Organisations that fail to adhere to the tenets of the Data Protection Act 2018 or the Data (Use and Access) Act 2025 can unnecessarily put people at risk of harm and face severe penalties.<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-further-resources\">Further Resources:<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.highspeedtraining.co.uk\/courses\/business-essentials\/data-protection-course\/\" target=\"_blank\" rel=\"noreferrer noopener\">Data Protection &amp; UK GDPR Training<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.highspeedtraining.co.uk\/hub\/data-use-and-access-act-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\">The Data (Use and Access) Act (DUAA) 2025 Summary<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.highspeedtraining.co.uk\/hub\/lack-of-training-in-the-workplace\/\" target=\"_blank\" rel=\"noreferrer noopener\">The Consequences of a Lack of Training in the Workplace<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The Data Protection Act 2018 is a key piece of legislation in the UK that governs data protection. Learn more about its core principles here.<\/p>\n","protected":false},"author":72,"featured_media":83122,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[3386,68],"class_list":["post-123","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","tag-data-protection","tag-financial"],"acf":{"schema_disabled":false,"schema_properties_FAQPage_question_answer":null,"schema_properties_HowTo_howto_tools":null,"schema_properties_HowTo_howto_supplies":null,"schema_properties_HowTo_howto_steps":null,"schema_properties_WebPage_cssSelector":null,"schema_sameAs_repeater":null,"schema_custom_json_repeater":null,"schema_custom_json_override":false},"hub":{"article_type":"Article","read_time":"5","enable_quiz":false,"quiz_id":null,"quiz_heading":"","quiz_subtext":"","quiz_markup":"","enable_advert":true,"advert":{"id":27257,"url":"https:\/\/www.highspeedtraining.co.uk\/courses\/business-essentials\/data-protection-course\/","desktop_src":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2018\/03\/HST_Hub-Advert_DPOTC_GDPR.jpg","mobile_src":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2018\/03\/HST_Hub-Advert_DPOTC_GDPR_mobile-A.jpg","alt":""},"author":{"id":72,"display_name":"Rachel Gordon","slug":"rachelgordon","description":"Rachel is a Junior Copywriter at High Speed Training with extensive experience in the education and independent hospitality sector. Having worked with students to improve their Maths and English skills, Rachel has an in-depth understanding of different educational needs. She has also worked in the independent hospitality industry, working to advocate for and raise awareness of the independent food and drink businesses at the heart of local communities. Rachel is passionate about providing people with useful information to support their personal and professional development.","active":true,"circle_image":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2024\/10\/rachel-hub-colour.png","thumb_image":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2024\/10\/rachel-bw.png","favourite_post":null}},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v19.5 (Yoast SEO v19.12) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>What is the Data Protection Act? | Summary &amp; Key Principles<\/title>\n<meta name=\"description\" content=\"The Data Protection Act 2018 is a key piece of legislation in the UK that governs data protection. Learn more about its core principles here.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data Protection Act 2018: Summary &amp; Key Principles\" \/>\n<meta property=\"og:description\" content=\"The Data Protection Act 2018 is a key piece of legislation in the UK that governs data protection. Learn more about its core principles here.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/\" \/>\n<meta property=\"og:site_name\" content=\"The Hub | High Speed Training\" \/>\n<meta property=\"article:publisher\" content=\"http:\/\/www.facebook.com\/highspeedtraining\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-20T08:30:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-21T15:50:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2026\/07\/data-protection-act-summary-fb.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Rachel Gordon\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2026\/07\/data-protection-act-summary-twit.jpg\" \/>\n<meta name=\"twitter:creator\" content=\"@hst\" \/>\n<meta name=\"twitter:site\" content=\"@hst\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Rachel Gordon\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"What is the Data Protection Act? | Summary & Key Principles","description":"The Data Protection Act 2018 is a key piece of legislation in the UK that governs data protection. Learn more about its core principles here.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/","og_locale":"en_GB","og_type":"article","og_title":"Data Protection Act 2018: Summary &amp; Key Principles","og_description":"The Data Protection Act 2018 is a key piece of legislation in the UK that governs data protection. Learn more about its core principles here.","og_url":"https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/","og_site_name":"The Hub | High Speed Training","article_publisher":"http:\/\/www.facebook.com\/highspeedtraining\/","article_published_time":"2026-07-20T08:30:00+00:00","article_modified_time":"2026-07-21T15:50:25+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2026\/07\/data-protection-act-summary-fb.jpg","type":"image\/jpeg"}],"author":"Rachel Gordon","twitter_card":"summary_large_image","twitter_image":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2026\/07\/data-protection-act-summary-twit.jpg","twitter_creator":"@hst","twitter_site":"@hst","twitter_misc":{"Written by":"Rachel Gordon","Estimated reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/#article","isPartOf":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/"},"author":{"name":"Rachel Gordon","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#\/schema\/person\/157e86aba3af84cf8c6c46f1577333fd"},"headline":"Data Protection Act 2018: Summary &amp; Key Principles","datePublished":"2026-07-20T08:30:00+00:00","dateModified":"2026-07-21T15:50:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/"},"wordCount":863,"commentCount":3,"publisher":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#organization"},"keywords":["Data Protection","Financial"],"articleSection":["Business"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/","url":"https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/","name":"What is the Data Protection Act? | Summary & Key Principles","isPartOf":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#website"},"datePublished":"2026-07-20T08:30:00+00:00","dateModified":"2026-07-21T15:50:25+00:00","description":"The Data Protection Act 2018 is a key piece of legislation in the UK that governs data protection. Learn more about its core principles here.","breadcrumb":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/data-protection-act-summary\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.highspeedtraining.co.uk\/hub\/"},{"@type":"ListItem","position":2,"name":"Data Protection Act 2018: Summary &amp; Key Principles"}]},{"@type":"WebSite","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#website","url":"https:\/\/www.highspeedtraining.co.uk\/hub\/","name":"The Hub | High Speed Training","description":"Welcome to the Hub, the company blog from High Speed Training.","publisher":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.highspeedtraining.co.uk\/hub\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#organization","name":"The Hub | High Speed Training","url":"https:\/\/www.highspeedtraining.co.uk\/hub\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#\/schema\/logo\/image\/","url":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2021\/05\/HST_Logo_Dark-Blue_CMYK_AW-scaled.jpg","contentUrl":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-content\/uploads\/2021\/05\/HST_Logo_Dark-Blue_CMYK_AW-scaled.jpg","width":2560,"height":1206,"caption":"The Hub | High Speed Training"},"image":{"@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#\/schema\/logo\/image\/"},"sameAs":["http:\/\/www.facebook.com\/highspeedtraining\/","https:\/\/twitter.com\/hst"]},{"@type":"Person","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#\/schema\/person\/157e86aba3af84cf8c6c46f1577333fd","name":"Rachel Gordon","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.highspeedtraining.co.uk\/hub\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/662a50c56a519b6fc9f09d20323c3cf3?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/662a50c56a519b6fc9f09d20323c3cf3?s=96&d=mm&r=g","caption":"Rachel Gordon"},"description":"Rachel is a Junior Copywriter at High Speed Training with extensive experience in the education and independent hospitality sector. Having worked with students to improve their Maths and English skills, Rachel has an in-depth understanding of different educational needs. She has also worked in the independent hospitality industry, working to advocate for and raise awareness of the independent food and drink businesses at the heart of local communities. Rachel is passionate about providing people with useful information to support their personal and professional development.","url":"https:\/\/www.highspeedtraining.co.uk\/hub\/author\/rachelgordon\/"}]}},"_links":{"self":[{"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/posts\/123","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/users\/72"}],"replies":[{"embeddable":true,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/comments?post=123"}],"version-history":[{"count":21,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/posts\/123\/revisions"}],"predecessor-version":[{"id":83141,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/posts\/123\/revisions\/83141"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/media\/83122"}],"wp:attachment":[{"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/media?parent=123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/categories?post=123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.highspeedtraining.co.uk\/hub\/wp-json\/wp\/v2\/tags?post=123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}