For ordinary controller and processor activity, start with the UK GDPR and then check the Data Protection Act 2018 for UK conditions, exemptions, powers, procedure, remedies, and offences.
For competent-authority law-enforcement processing or intelligence-services processing, use the separate regimes in Parts 3 and 4 of the 2018 Act.
The UK GDPR and Data Protection Act 2018 are complementary, not competing laws. The UK GDPR supplies the main rules for general processing: principles, lawful bases, transparency, rights, controller and processor duties, security, breaches, transfers, and administrative fines. The 2018 Act supplements those rules with UK-specific conditions and exemptions, regulates enforcement and remedies, and creates separate regimes for law-enforcement processing and intelligence-services processing. Later legislation, including the Data (Use and Access) Act 2025, has amended both instruments, so use their current consolidated text. A sound decision identifies the applicable UK GDPR article and the exact DPA 2018 provision that changes or completes the answer.
Side-by-side comparison
UK GDPR vs Data Protection Act 2018
Compare their scope, roles, conditions, exemptions, evidence, enforcement, and decision sequence.
Sets principles, lawful bases, transparency, individual rights, accountability, processor duties, security, breach, transfer, and fine rules for general processing.
Controllers and processors own most operational duties; data subjects, representatives, DPOs, recipients, and the Commissioner also have defined roles.
Sets principles, lawful bases, transparency, individual rights, accountability, processor duties, security, breach, transfer, and fine rules for general processing.
Controllers and processors own most operational duties; data subjects, representatives, DPOs, recipients, and the Commissioner also have defined roles.
Most commercial, charitable, public-sector, and employment processing falls within the general-processing regime: the UK GDPR together with Part 2 of the DPA 2018. The organisation should identify its controller or processor role, purpose, lawful basis, transparency duties, rights handling, retention, security, processor terms, and transfers under the UK GDPR, then check whether the 2018 Act supplies an additional condition, safeguard, or exemption.
Part 3 of the DPA 2018 applies to processing by a for a law-enforcement purpose. Part 4 applies to intelligence-services processing. A public body does not enter Part 3 merely because its work has a public-safety connection; both the statutory competent-authority status and the law-enforcement purpose matter.
General processing: use the UK GDPR and DPA 2018 Part 2 together.
Law-enforcement processing: test the definitions in DPA 2018 Part 3 before applying that regime.
Intelligence-services processing: use DPA 2018 Part 4.
Keep separate records when one organisation carries out activities under more than one regime.
Article 9 UK GDPR prohibits special-category processing unless an Article 9(2) condition applies. Where that condition requires authorisation by domestic law, section 10 and Schedule 1 of the DPA 2018 provide detailed UK conditions and, for some conditions, require an appropriate policy document. Criminal-offence data also requires Article 10 authority and the applicable DPA 2018 route.
Schedules 2 to 4 contain exemptions and restrictions for defined purposes and circumstances. They do not erase the UK GDPR wholesale. Record the provision relied on, the facts that satisfy each condition, which right or duty is affected, why applying it is necessary where the provision requires that test, and what can still be provided to the person.
For special-category or criminal-offence data, record both the UK GDPR condition and the DPA 2018 condition or authority.
Where Schedule 1 requires an appropriate policy document, keep the document and the retention and erasure explanation it must contain.
For an exemption, cite the exact paragraph and affected provision; do not record only 'DPA exemption'.
Reassess an exemption for each request or disclosure because its application can depend on the purpose, prejudice, necessity, and current facts.
Link each processing decision to its UK GDPR article, any DPA 2018 condition or exemption, the responsible owner, and the evidence that satisfies the rule.