UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025
Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
A comprehensive regime rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Establish and document a lawful basis under UK General Data Protection Regulation (GDPR) Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
- Do not rely on the recognised legitimate interests basis if you are a public authority exercising your own core functions; a necessity test still applies even though no balancing test is required.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Knowingly or recklessly obtaining, disclosing, procuring the disclosure of, or (after obtaining) retaining personal data without the controller's consent is an offence under DPA 2018 s.170, as is selling or offering to sell personal data obtained in those circumstances. A separate offence under s.173 covers altering, defacing, blocking, erasing, destroying or concealing information to prevent its disclosure following a data-subject access request. Both carry an unlimited fine on summary conviction in England and Wales or on conviction on indictment, or a fine not exceeding the statutory maximum on summary conviction in Scotland or Northern Ireland (s.196), with no term of imprisonment.
Penalty structure
The Act's general ceiling: UK GDPR Art. 83(5) sets administrative fines up to the higher of £17,500,000 or 4% of worldwide annual turnover for infringement of the basic principles for processing, including conditions for consent (Arts. 5, 6, 7 and 9), matching the higher maximum amount fixed by DPA 2018 s.157(5). Narrower provisions of this Act (breach notification, Arts. 33-34) attract the lower standard maximum amount instead; see the article-scoped instrument rows in this file for those tiers.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- GBP
- Fixed cap
- 17,500,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Information Commissioner's Office (ICO), the UK's single supervisory authority for data protection and PECR, exercising the Article 57 tasks and Article 58 powers conferred on the Commissioner by Data Protection Act 2018 s.115.
Enforcement record
Hand count from the ICO's own enforcement action register (Type facet Monetary penalties plus Enforcement notices), read across the register's first two pages (50 of 222 total listed actions of every type), which cover 7 August 2026 back to 24 April 2025, past the twelve-month cutoff. In the twelve months ending 7 August 2026 (the register's most recent entry), the ICO published 18 monetary penalty notices and 14 enforcement notices, for a combined actions_per_year of 32. Reprimands and prosecutions are excluded. Where the register lists a monetary penalty notice and an enforcement notice against the same underlying matter as two separate rows (for example Elderly Aids Limited, 6 August 2026), each row counts once as its own published enforcement instrument. fines_per_year is omitted: several monetary penalty rows in the register's list view state no penalty figure in the summary text shown there (only the full decision notice states it), so a sum from the visible list would understate the true total. This is the ICO's enforcement record for the data protection and PECR regime generally, not a record specific to this instrument's own provisions.
- As of
- 2 September 2026
- Source link
- https://ico.org.uk/action-weve-taken/enforcement/
- Actions per year
- 32
What it reaches
Obligation class
Consent, Disclosure, DPIA, Data subject rights, Transfer, Breach notice, Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The UK retained a copy of the General Data Protection Regulation (GDPR) at Brexit (UK GDPR) alongside the Data Protection Act 2018 (DPA 2018), but that copy has now materially diverged: the Data (Use and Access) Act 2025 (DUA Act, Royal Assent 19 June 2025), whose main data protection reforms took effect 5 February 2026, added a new closed-list "recognised legitimate interests" lawful basis (Article 6(1)(ea)) needing no balancing test, for purposes such as safeguarding, crime prevention, emergencies, national security, direct marketing, and intra-group administrative sharing.
This basis is unavailable to a public authority exercising its own core functions, and has no equivalent in the EU GDPR Article 6 list.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
legislation.gov.uk, official consolidated text
ICO Data (Use and Access) Act 2025 summary
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.