UK

DPA 2018: Scope and Application

Scope and Application [Part 1-2]

Rule: The DPA 2018 supplements the UK GDPR for general processing, provides a complete regime for law enforcement and intelligence services, and sets out exemptions and enforcement mechanisms.

Structure of the DPA 2018

PartCoverageRelationship to UK GDPR
Part 1Preliminary (definitions)Foundational
Part 2General processingSupplements UK GDPR
Part 3Law enforcement processingStandalone (not GDPR)
Part 4Intelligence services processingStandalone (not GDPR)
Part 5Information CommissionerApplies to all parts
Part 6EnforcementApplies to all parts
Part 7Supplementary provisionsApplies to all parts

How Part 2 Works with UK GDPR [s.4-5]

Part 2 applies the UK GDPR with supplementary provisions:

“The GDPR, the applied GDPR and this Part of this Act apply in relation to the processing of personal data.”

Supplementary provisions include:

  • Lawful bases for special category data (Schedule 1)
  • Exemptions from data subject rights (Schedule 2)
  • Accreditation of certification providers
  • Codes of practice

When Part 3 Applies Instead [s.29-30]

Part 3 applies to processing by competent authorities for law enforcement purposes:

TermDefinition
Competent authorityPerson listed in Schedule 7 (police, prosecution, courts, etc.)
Law enforcement purposePrevention, investigation, detection, prosecution of criminal offenses; execution of criminal penalties

Key differences from UK GDPR:

AspectUK GDPR (Part 2)Part 3 (Law Enforcement)
Legal bases6 lawful basesDifferent bases (s.35)
Special categoriesExplicit consent or conditionsStrict necessity + conditions
International transfersAdequacy or safeguardsAdequacy or specific conditions
Right to erasureApplies with exceptionsMore limited

Territorial Scope [s.207]

The DPA 2018 applies to:

  • Controllers/processors established in the UK
  • Processing of UK residents’ data by non-UK controllers (for Part 2)
  • UK law enforcement bodies (for Part 3)

Key Definitions [s.3]

TermDefinition
Personal dataSame as UK GDPR Art 4(1)
ProcessingSame as UK GDPR Art 4(2)
ControllerSame as UK GDPR Art 4(7)
ProcessorSame as UK GDPR Art 4(8)
The CommissionerInformation Commissioner

Relationship Summary

General Processing (businesses, public sector):
    UK GDPR + DPA 2018 Part 2

Law Enforcement Processing (police, prosecutors):
    DPA 2018 Part 3 only

Intelligence Services (MI5, MI6, GCHQ):
    DPA 2018 Part 4 only

Citation

Parts 1-2, Data Protection Act 2018

Contains public sector information licensed under the Open Government Licence v3.0 where applicable. This is not legal advice. Always refer to official sources for authoritative text.

llms.txt