Artifact GuideUKUK GDPR vs DPA 2018

UK GDPR vs Data Protection Act 2018

For ordinary controller and processor activity, start with the UK GDPR and then check the Data Protection Act 2018 for UK conditions, exemptions, powers, procedure, remedies, and offences.

For competent-authority law-enforcement processing or intelligence-services processing, use the separate regimes in Parts 3 and 4 of the 2018 Act.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
15

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The UK GDPR and Data Protection Act 2018 are complementary, not competing laws. The UK GDPR supplies the main rules for general processing: principles, lawful bases, transparency, rights, controller and processor duties, security, breaches, transfers, and administrative fines. The 2018 Act supplements those rules with UK-specific conditions and exemptions, regulates enforcement and remedies, and creates separate regimes for law-enforcement processing and intelligence-services processing. Later legislation, including the Data (Use and Access) Act 2025, has amended both instruments, so use their current consolidated text. A sound decision identifies the applicable UK GDPR article and the exact DPA 2018 provision that changes or completes the answer.

Side-by-side comparison

UK GDPR vs Data Protection Act 2018

Compare their scope, roles, conditions, exemptions, evidence, enforcement, and decision sequence.

Review all sources
First framework
UK GDPR

The main rules for general processing by controllers and processors.

Second framework
Data Protection Act 2018

The domestic Act that supplements general processing and creates separate law-enforcement and intelligence-services regimes.

Comparison row 1

Scope

UK GDPR

Governs general processing within its material and territorial scope, subject to the domestic provisions that supplement or restrict it.

Data Protection Act 2018

Part 2 supplements general processing; Parts 3 and 4 separately govern law-enforcement and intelligence-services processing.

Operational implication

Classify the processing regime before choosing the rule.

Comparison row 2

Baseline rules

UK GDPR

Sets principles, lawful bases, transparency, individual rights, accountability, processor duties, security, breach, transfer, and fine rules for general processing.

Data Protection Act 2018

Defines domestic terms, conditions, safeguards, exemptions, regulatory procedure, remedies, and offences that complete the UK framework.

Operational implication

For general processing, cite both instruments when the answer depends on a domestic condition or exemption.

Comparison row 3

Special-category and criminal-offence data

UK GDPR

Articles 9 and 10 set the general restrictions and identify when domestic law must authorise or condition processing.

Data Protection Act 2018

Section 10 and Schedule 1 provide detailed UK conditions and safeguards, including an appropriate policy document for specified conditions.

Operational implication

Record both layers; a lawful basis under Article 6 does not by itself authorise special-category or criminal-offence processing.

Comparison row 4

Exemptions

UK GDPR

Rights and duties apply unless a valid statutory restriction or exemption affects the specific provision.

Data Protection Act 2018

Schedules 2-4 provide defined exemptions for specified purposes, data, and circumstances.

Operational implication

Document the exact exemption, its conditions, the affected UK GDPR provision, and the decision for the particular facts.

Comparison row 5

Who acts

UK GDPR

Controllers and processors own most operational duties; data subjects, representatives, DPOs, recipients, and the Commissioner also have defined roles.

Data Protection Act 2018

The applicable Part may assign duties to a controller, , intelligence service, the Commissioner, a tribunal, or a court.

Operational implication

Name the actor and processing regime in each record instead of using 'the organisation' for every duty.

Comparison row 6

Enforcement and remedies

UK GDPR

Sets supervisory powers, data-subject remedies, compensation, and the administrative-fine framework at regulation level.

Data Protection Act 2018

Part 5 establishes the Commissioner; Part 6 contains notices, appeals, complaints, court remedies, compensation provisions, and offences.

Operational implication

Check the current Act for the procedure and remedy attached to a UK GDPR breach.

Practical decision rule

How should a team apply the two instruments?

  • Classify the activity as general, law-enforcement, or intelligence-services processing.
  • For general processing, identify the UK GDPR duty first, then add any DPA 2018 condition, safeguard, exemption, procedure, remedy, or offence.
  • Record the exact provisions and facts rather than treating 'UK GDPR compliance' or 'DPA compliance' as a single conclusion.
Section 1

Start with the processing regime

Most commercial, charitable, public-sector, and employment processing falls within the general-processing regime: the UK GDPR together with Part 2 of the DPA 2018. The organisation should identify its controller or processor role, purpose, lawful basis, transparency duties, rights handling, retention, security, processor terms, and transfers under the UK GDPR, then check whether the 2018 Act supplies an additional condition, safeguard, or exemption.

Part 3 of the DPA 2018 applies to processing by a for a law-enforcement purpose. Part 4 applies to intelligence-services processing. A public body does not enter Part 3 merely because its work has a public-safety connection; both the statutory competent-authority status and the law-enforcement purpose matter.

  • General processing: use the UK GDPR and DPA 2018 Part 2 together.
  • Law-enforcement processing: test the definitions in DPA 2018 Part 3 before applying that regime.
  • Intelligence-services processing: use DPA 2018 Part 4.
  • Keep separate records when one organisation carries out activities under more than one regime.
Section 2

Check the exact DPA 2018 condition or exemption

Article 9 UK GDPR prohibits special-category processing unless an Article 9(2) condition applies. Where that condition requires authorisation by domestic law, section 10 and Schedule 1 of the DPA 2018 provide detailed UK conditions and, for some conditions, require an appropriate policy document. Criminal-offence data also requires Article 10 authority and the applicable DPA 2018 route.

Schedules 2 to 4 contain exemptions and restrictions for defined purposes and circumstances. They do not erase the UK GDPR wholesale. Record the provision relied on, the facts that satisfy each condition, which right or duty is affected, why applying it is necessary where the provision requires that test, and what can still be provided to the person.

  • For special-category or criminal-offence data, record both the UK GDPR condition and the DPA 2018 condition or authority.
  • Where Schedule 1 requires an appropriate policy document, keep the document and the retention and erasure explanation it must contain.
  • For an exemption, cite the exact paragraph and affected provision; do not record only 'DPA exemption'.
  • Reassess an exemption for each request or disclosure because its application can depend on the purpose, prejudice, necessity, and current facts.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Provides the baseline general-processing rules.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.