Law / United Kingdom

UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025

Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

A comprehensive regime rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Establish and document a lawful basis under UK General Data Protection Regulation (GDPR) Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
  • Do not rely on the recognised legitimate interests basis if you are a public authority exercising your own core functions; a necessity test still applies even though no balancing test is required.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Knowingly or recklessly obtaining, disclosing, procuring the disclosure of, or (after obtaining) retaining personal data without the controller's consent is an offence under DPA 2018 s.170, as is selling or offering to sell personal data obtained in those circumstances. A separate offence under s.173 covers altering, defacing, blocking, erasing, destroying or concealing information to prevent its disclosure following a data-subject access request. Both carry an unlimited fine on summary conviction in England and Wales or on conviction on indictment, or a fine not exceeding the statutory maximum on summary conviction in Scotland or Northern Ireland (s.196), with no term of imprisonment.

Penalty structure

The Act's general ceiling: UK GDPR Art. 83(5) sets administrative fines up to the higher of £17,500,000 or 4% of worldwide annual turnover for infringement of the basic principles for processing, including conditions for consent (Arts. 5, 6, 7 and 9), matching the higher maximum amount fixed by DPA 2018 s.157(5). Narrower provisions of this Act (breach notification, Arts. 33-34) attract the lower standard maximum amount instead; see the article-scoped instrument rows in this file for those tiers.

Rule
Higher of
As of
2 September 2026
Currency
GBP
Fixed cap
17,500,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Information Commissioner's Office (ICO), the UK's single supervisory authority for data protection and PECR, exercising the Article 57 tasks and Article 58 powers conferred on the Commissioner by Data Protection Act 2018 s.115.

Enforcement record

Hand count from the ICO's own enforcement action register (Type facet Monetary penalties plus Enforcement notices), read across the register's first two pages (50 of 222 total listed actions of every type), which cover 7 August 2026 back to 24 April 2025, past the twelve-month cutoff. In the twelve months ending 7 August 2026 (the register's most recent entry), the ICO published 18 monetary penalty notices and 14 enforcement notices, for a combined actions_per_year of 32. Reprimands and prosecutions are excluded. Where the register lists a monetary penalty notice and an enforcement notice against the same underlying matter as two separate rows (for example Elderly Aids Limited, 6 August 2026), each row counts once as its own published enforcement instrument. fines_per_year is omitted: several monetary penalty rows in the register's list view state no penalty figure in the summary text shown there (only the full decision notice states it), so a sum from the visible list would understate the true total. This is the ICO's enforcement record for the data protection and PECR regime generally, not a record specific to this instrument's own provisions.

As of
2 September 2026
Source link
https://ico.org.uk/action-weve-taken/enforcement/
Actions per year
32

What it reaches

Obligation class

Consent, Disclosure, DPIA, Data subject rights, Transfer, Breach notice, Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The UK retained a copy of the General Data Protection Regulation (GDPR) at Brexit (UK GDPR) alongside the Data Protection Act 2018 (DPA 2018), but that copy has now materially diverged: the Data (Use and Access) Act 2025 (DUA Act, Royal Assent 19 June 2025), whose main data protection reforms took effect 5 February 2026, added a new closed-list "recognised legitimate interests" lawful basis (Article 6(1)(ea)) needing no balancing test, for purposes such as safeguarding, crime prevention, emergencies, national security, direct marketing, and intra-group administrative sharing.

This basis is unavailable to a public authority exercising its own core functions, and has no equivalent in the EU GDPR Article 6 list.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

legislation.gov.uk, official consolidated text
ICO Data (Use and Access) Act 2025 summary

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app