Search Legislation

Data Protection Act 2018

 Help about what version

What Version

 Help about advanced features

Advanced Features

Changes to legislation:

Data Protection Act 2018, CHAPTER 1 is up to date with all changes known to be in force on or before 06 March 2026. There are changes that may be brought into force at a future date. Changes that have been made appear in the content and are referenced with annotations. Help about Changes to Legislation

Close

Changes to Legislation

Revised legislation carried on this site may not be fully up to date. Changes and effects are recorded by our editorial team in lists which can be found in the ‘Changes to Legislation’ area. Where those effects have yet to be applied to the text of the legislation by the editorial team they are also listed alongside the legislation in the affected provisions. Use the ‘more’ link to open the changes and effects relevant to the provision you are viewing.

View outstanding changes

Changes and effects yet to be applied to Part 4 Chapter 1:

Changes and effects yet to be applied to the whole Act associated Parts and Chapters:

Whole provisions yet to be inserted into this Act (including any effects on those provisions):

CHAPTER 1U.K.Scope and definitions

ScopeU.K.

82Processing to which this Part appliesU.K.

[F1(A1)This Part—

(a)applies to processing of personal data by an intelligence service, and

(b)applies to processing of personal data by a qualifying competent authority where the processing is the subject of a designation notice that is for the time being in force (see sections 82A to 82E).]

(1)This Part applies [F2only] to—

(a)[F3processing] of personal data wholly or partly by automated means, and

(b)[F4processing] otherwise than by automated means of personal data which forms part of a filing system or is intended to form part of a filing system.

(2)In this Part, “intelligence service” means—

(a)the Security Service;

(b)the Secret Intelligence Service;

(c)the Government Communications Headquarters.

[F5(2A)In this Part—

  • competent authority” has the same meaning as in Part 3;

  • qualifying competent authority” means a competent authority specified or described in regulations made by the Secretary of State.]

(3)A reference in this Part to the processing of personal data is to processing to which this Part applies.

[F6(4)Regulations under this section are subject to the affirmative resolution procedure.]

Textual Amendments

F5S. 82(2A) inserted (19.6.2025 for specified purposes, 17.11.2025 in so far as not already in force) by Data (Use and Access) Act 2025 (c. 18), ss. 89(2)(c), 142(1)(2)(h); S.I. 2025/996, reg. 2(2)(a)

F6S. 82(4) inserted (19.6.2025 for specified purposes, 17.11.2025 in so far as not already in force) by Data (Use and Access) Act 2025 (c. 18), ss. 89(2)(d), 142(1)(2)(h); S.I. 2025/996, reg. 2(2)(a)

Commencement Information

I1S. 82 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)

[F782ADesignation of processing by a qualifying competent authorityU.K.

(1)For the purposes of this Part, the Secretary of State may give a notice designating processing of personal data by a qualifying competent authority (a “designation notice”) where—

(a)an application for designation of the processing is made in accordance with this section, and

(b)the Secretary of State considers that designation of the processing is required for the purposes of safeguarding national security.

(2)The Secretary of State may only designate processing by a qualifying competent authority that is carried out by the authority as a joint controller with at least one intelligence service.

(3)The Secretary of State may not designate processing by a qualifying competent authority that consists of the transfer of personal data to—

(a)a country or territory outside the United Kingdom, or

(b)an international organisation.

(4)A designation notice must—

(a)specify or describe the processing and qualifying competent authority that are designated, and

(b)be given to the applicants for the designation (and see also section 82D).

(5)An application for designation of processing of personal data by a qualifying competent authority must be made jointly by—

(a)the qualifying competent authority, and

(b)the intelligence service with which the processing is to be carried out.

(6)An application may be made in respect of more than one qualifying competent authority and in respect of processing with more than one intelligence service.

(7)The application must—

(a)describe the processing, including the intended purposes and means of processing, and

(b)explain why the applicants consider that designation is required for the purposes of safeguarding national security.

(8)Before giving a designation notice, the Secretary of State must consult the Commissioner.

(9)In this section, “joint controller”, in relation to processing of personal data, means a controller whose responsibilities for compliance with this Part in relation to the processing are determined in an arrangement under section 104.]

[F782BDuration of designation noticeU.K.

(1)A designation notice must state when it comes into force.

(2)A designation notice ceases to be in force at the earliest of the following times—

(a)at the end of the period of 5 years beginning when the notice comes into force;

(b)(if relevant) at the end of a shorter period specified in the notice;

(c)when the notice is withdrawn under section 82C.

(3)The Secretary of State may give a further designation notice in respect of processing that is, or has been, the subject of a previous designation notice.]

[F782CReview and withdrawal of designation noticeU.K.

(1)Subsections (2) to (4) apply where processing is the subject of a designation notice for the time being in force.

(2)A person who applied for the designation of the processing must notify the Secretary of State without undue delay if the person considers that the designation is no longer required for the purposes of safeguarding national security.

(3)A person who applied for the designation of the processing must, on a request from the Secretary of State, provide—

(a)a description of the processing that is being, or is intended to be, carried out in reliance on the notice, and

(b)an explanation of why the person considers that designation of the processing continues to be required for the purposes of safeguarding national security.

(4)The Secretary of State must at least annually—

(a)review each designation notice that is for the time being in force, and

(b)consider whether designation of the processing which is the subject of the notice continues to be required for the purposes of safeguarding national security.

(5)The Secretary of State—

(a)may withdraw a designation notice by giving a further notice (a “withdrawal notice”) to the persons who applied for the designation, and

(b)must give a withdrawal notice if the Secretary of State considers that designation of some or all of the processing to which the notice applies is no longer required for the purposes of safeguarding national security (whether as a result of a review required under subsection (4) or otherwise).

(6)A withdrawal notice must—

(a)withdraw the designation notice completely, and

(b)state when it comes into force.

(7)In determining when a withdrawal notice required under subsection (5)(b) comes into force, the Secretary of State must consider—

(a)the desirability of the processing ceasing to be designated as soon as possible, and

(b)where relevant, the time needed to effect an orderly transition to new arrangements for the processing of personal data.]

[F782DRecords of designation noticesU.K.

(1)Where the Secretary of State gives a designation notice—

(a)the Secretary of State must send a copy of the notice to the Commissioner, and

(b)the Commissioner must publish a record of the notice.

(2)The record must contain—

(a)the Secretary of State’s name,

(b)the date on which the notice was given,

(c)the date on which the notice ceases to have effect (if not previously withdrawn), and

(d)subject to subsection (3), the rest of the text of the notice.

(3)The Commissioner must not publish the text, or a part of the text, of the notice if—

(a)the Secretary of State has determined that publishing the text or that part of the text—

(i)would be against the interests of national security,

(ii)would be contrary to the public interest, or

(iii)might jeopardise the safety of any person, and

(b)the Secretary of State has notified the Commissioner of that determination.

(4)The Commissioner must keep the record of the notice available to the public while the notice is in force.

(5)Where the Secretary of State gives a withdrawal notice, the Secretary of State must send a copy of the notice to the Commissioner.]

[F782EAppeal against designation noticeU.K.

(1)A person directly affected by a designation notice may appeal to the Tribunal against the notice.

(2)If, on an appeal under this section, the Tribunal finds that, applying the principles applied by a court on an application for judicial review, the Secretary of State did not have reasonable grounds for giving the notice, the Tribunal may—

(a)allow the appeal, and

(b)quash the notice.]

DefinitionsU.K.

83Meaning of “controller” and “processor”U.K.

[F8(A1)For the purposes of this Part—

(a)an intelligence service is the “controller” in relation to the processing of personal data if it satisfies subsection (1) alone or jointly with others, and

(b)a qualifying competent authority is the “controller” in relation to the processing of personal data that is the subject of a designation notice that is for the time being in force if the authority satisfies subsection (1) jointly with others.]

(1)[F9This subsection is satisfied by a person who—]

(a)determines the purposes and means of the processing of personal data, or

(b)is the controller by virtue of subsection (2).

(2)Where personal data is processed only—

(a)for purposes for which it is required by an enactment to be processed, and

(b)by means by which it is required by an enactment to be processed,

the [F10person on whom] the obligation to process the data is imposed by the enactment (or, if different, one of the enactments) is the controller.

(3)In this Part, “processor” means any person who processes personal data on behalf of the controller (other than a person who is an employee of the controller).

Textual Amendments

Commencement Information

I2S. 83 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)

84Other definitionsU.K.

(1)This section defines other expressions used in this Part.

(2)Consent”, in relation to the processing of personal data relating to an individual, means a freely given, specific, informed and unambiguous indication of the individual's wishes by which the individual, by a statement or by a clear affirmative action, signifies agreement to the processing of the personal data.

[F11(2A)Designation notice” has the meaning given in section 82A.]

(3)Employee”, in relation to any person, includes an individual who holds a position (whether paid or unpaid) under the direction and control of that person.

(4)Personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

(5)Recipient”, in relation to any personal data, means any person to whom the data is disclosed, whether a third party or not, but it does not include a person to whom disclosure is or may be made in the framework of a particular inquiry in accordance with the law.

(6)Restriction of processing” means the marking of stored personal data with the aim of limiting its processing for the future.

[F12(6A)Sensitive processing” has the meaning given in section 86(7).]

[F13(6B)Withdrawal notice” has the meaning given in section 82C.]

(7)Sections 3 and 205 include definitions of other expressions used in this Part.

Back to top

Options/Help

Print Options

You have chosen to open The Whole Act

The Whole Act you have selected contains over 200 provisions and might take some time to download. You may also experience some issues with your browser, such as an alert box that a script is taking a long time to run.

Would you like to continue?

You have chosen to open The Whole Act as a PDF

The Whole Act you have selected contains over 200 provisions and might take some time to download.

Would you like to continue?

You have chosen to open The Whole Act without Schedules

The Whole Act without Schedules you have selected contains over 200 provisions and might take some time to download. You may also experience some issues with your browser, such as an alert box that a script is taking a long time to run.

Would you like to continue?

You have chosen to open The Whole Act without Schedules as a PDF

The Whole Act without Schedules you have selected contains over 200 provisions and might take some time to download.

Would you like to continue?

You have chosen to open the Whole Act

The Whole Act you have selected contains over 200 provisions and might take some time to download. You may also experience some issues with your browser, such as an alert box that a script is taking a long time to run.

Would you like to continue?

You have chosen to open the Whole Act without Schedules

The Whole Act without Schedules you have selected contains over 200 provisions and might take some time to download. You may also experience some issues with your browser, such as an alert box that a script is taking a long time to run.

Would you like to continue?

You have chosen to open Schedules only

The Schedules you have selected contains over 200 provisions and might take some time to download. You may also experience some issues with your browser, such as an alert box that a script is taking a long time to run.

Would you like to continue?

Close

Legislation is available in different versions:

Latest Available (revised):The latest available updated version of the legislation incorporating changes made by subsequent legislation and applied by our editorial team. Changes we have not yet applied to the text, can be found in the ‘Changes to Legislation’ area.

Original (As Enacted or Made): The original version of the legislation as it stood when it was enacted or made. No changes have been applied to the text.

Close

See additional information alongside the content

Geographical Extent: Indicates the geographical area that this provision applies to. For further information see ‘Frequently Asked Questions’.

Show Timeline of Changes: See how this legislation has or could change over time. Turning this feature on will show extra navigation options to go to these specific points in time. Return to the latest available version by using the controls above in the What Version box.

Close

Opening Options

Different options to open legislation in order to view more content on screen at once

Close

Explanatory Notes

Text created by the government department responsible for the subject matter of the Act to explain what the Act sets out to achieve and to make the Act accessible to readers who are not legally qualified. Explanatory Notes were introduced in 1999 and accompany all Public Acts except Appropriation, Consolidated Fund, Finance and Consolidation Acts.

Close

More Resources

Access essential accompanying documents and information for this legislation item from this tab. Dependent on the legislation item being viewed this may include:

  • the original print PDF of the as enacted version that was used for the print copy
  • lists of changes made by and/or affecting this legislation item
  • confers power and blanket amendment details
  • all formats of all associated documents
  • correction slips
  • links to related legislation and further information resources
Close

Timeline of Changes

This timeline shows the different points in time where a change occurred. The dates will coincide with the earliest date on which the change (e.g an insertion, a repeal or a substitution) that was applied came into force. The first date in the timeline will usually be the earliest date when the provision came into force. In some cases the first date is 01/02/1991 (or for Northern Ireland legislation 01/01/2006). This date is our basedate. No versions before this date are available. For further information see the Editorial Practice Guide and Glossary under Help.

Close

More Resources

Use this menu to access essential accompanying documents and information for this legislation item. Dependent on the legislation item being viewed this may include:

  • the original print PDF of the as enacted version that was used for the print copy
  • correction slips

Click 'View More' or select 'More Resources' tab for additional information including:

  • lists of changes made by and/or affecting this legislation item
  • confers power and blanket amendment details
  • all formats of all associated documents
  • links to related legislation and further information resources